Table of Contents
- Why AI Governance Policy Is the Committee Topic of the Decade
- What AI Governance Policy Actually Means
- Traffic rules
- School policies
- International treaties
- The Global Frameworks Every Student Should Know
- OECD AI Principles
- NIST AI Risk Management Framework
- ISO/IEC 42001
- UN General Assembly resolution
- Comparing the EU, U.S., and Emerging Bloc Approaches
- Three negotiating positions
- The Agentic AI Governance Gap
- What can go wrong
- Global South Capacity and the New Multipolar Order
- From one center to several negotiating tracks
- A Student Toolkit for Policy Debate and Research
- A compact research ladder
- Open Questions That Will Define the Next Decade

Do not index
Do not index
You arrive at a Model UN committee expecting a familiar debate about human rights, development, or international security. Instead, the crisis update says that an autonomous AI system has been deployed in a member state's welfare system without prior clearance. It has already influenced public decisions, but no delegate can identify who authorized it, who tested it, or who can stop it.
That situation turns AI governance policy into a procedural question. Do you invoke existing human rights commitments? Draft an emergency resolution? Ask a technical body to investigate? Or postpone the issue until governments understand the technology better? The same choices now confront policymakers, regulators, companies, and civil society.
Why AI Governance Policy Is the Committee Topic of the Decade
In a committee room, the first mistake would be to treat the system as only a technical problem. The second would be to treat it as only a legal problem. A welfare algorithm can involve data protection, administrative law, discrimination, public procurement, cybersecurity, and state accountability at the same time.
The chair would ask delegates to identify three things before they begin negotiating:
- The actor: Who designed, purchased, deployed, and supervised the system?
- The decision: What did the system do, and did a human official retain authority?
- The remedy: Can an affected person challenge the outcome, obtain an explanation, or receive compensation?
This is why AI governance has moved beyond specialist working groups. The OECD Council adopted its Recommendation on Artificial Intelligence on 22 May 2019, establishing the first intergovernmental standard on AI. The framework was revised in November 2023 and updated again in 2024, showing that governments treat governance as a continuing policy process rather than a document that can be filed away. The OECD's AI Principles provide five values-based principles and five recommendations for national policy and international cooperation.

The diplomatic agenda has also widened. On 21 March 2024, the UN General Assembly adopted its first standalone resolution on artificial intelligence without a vote. The resolution was co-sponsored by more than 120 Member States, and it urged governments, companies, civil society, research organizations, and the media to support governance frameworks for safe, secure, and trustworthy AI. The UN account of the resolution marks a shift from national experimentation toward multilateral discussion.
For students, that shift matters immediately. The questions appearing in New York and Geneva are also appearing in university policy teams, MUN position papers, technology committees, and early-career research roles. A useful starting point is to treat every AI deployment as a miniature international negotiation. Someone defines the rules, someone holds the resources, someone bears the risk, and someone must answer when the system fails.
For broader context on how technology is changing diplomacy, explore artificial intelligence in international relations. The most effective delegate won't ask whether AI is good or bad. They'll ask which institution has authority, which safeguard is enforceable, and which states are missing from the room.
What AI Governance Policy Actually Means
AI governance policy is the collection of laws, standards, institutional processes, and informal norms that shape how artificial intelligence is designed, deployed, and monitored. It answers practical questions: Who can approve a system? Which risks must be assessed? What records must be kept? Who investigates harm? What can an affected person do?
A three-layer analogy makes the concept easier to use in debate.
Traffic rules
Traffic rules govern shared behavior through enforceable limits. They determine where vehicles can operate, who has priority, and what happens after a collision. Binding legislation for high-risk AI systems occupies a similar place. It can impose duties on providers or users and give public authorities powers to inspect, penalize, or restrict deployment.
School policies
School policies sit closer to voluntary governance. A school may establish expectations for acceptable conduct, responsible technology use, or academic integrity without creating a national criminal code. Professional standards, corporate policies, and voluntary risk frameworks often work this way. They can shape behavior, create common language, and prepare organizations for stronger requirements, but their force depends on adoption and enforcement.
International treaties
International cooperation resembles a treaty layer. No single state can resolve every cross-border issue involving data, model supply chains, cybersecurity, or accountability. Governments therefore negotiate shared language, reporting practices, and cooperation mechanisms. A UN resolution may not impose the same duties as domestic legislation, but it can establish diplomatic expectations and guide later national action.

This layered model also separates governance from related concepts. AI ethics focuses primarily on values such as fairness, dignity, and human autonomy. AI strategy focuses on national competitiveness, research capacity, infrastructure, and economic goals. Governance is more operational. It asks who decides, who checks the decision, what evidence must exist, and who is accountable when the system causes harm.
A data security process belongs inside this operational layer because governance fails if an organization can't control the information its AI system uses. Teams building that foundation can consult MEDIAL's practical data security playbook for guidance on translating broad security responsibilities into working practices.
In committee, don't use “AI governance” as a synonym for every AI-related policy. Specify the layer and the actor. A national law may bind companies. A technical standard may guide procurement. An institutional process may give an internal review board authority. An international resolution may establish shared diplomatic expectations.
That discipline connects AI governance to the wider study of technology policy. It also helps delegates avoid a common error: presenting a principle such as transparency without explaining who must disclose what, to whom, and at which stage of the AI lifecycle.
The Global Frameworks Every Student Should Know
Four instruments anchor much of the international conversation, but they aren't interchangeable. Each resembles a different draft resolution in committee, with a different sponsor, legal status, and implementation mechanism.
OECD AI Principles
The OECD framework provides an early intergovernmental foundation for trustworthy AI. Its five high-level values-based principles address ideas such as human-centered values, transparency, security, and accountability. Its five recommendations focus on national policy and international cooperation. The framework is especially useful in a position paper because it gives delegates shared language without pretending that every country has identical legislation.
NIST AI Risk Management Framework
The NIST AI RMF is an operational risk-management structure. Its functions are Govern, Map, Measure, and Manage. The Govern function is particularly important because it requires organizations to establish policies, processes, procedures, and practices across the enterprise. NIST also emphasizes transparency and the documentation of legal and regulatory requirements. The NIST Govern function shows how a principle becomes a control system.
ISO/IEC 42001
ISO/IEC 42001 turns governance into a management-system exercise. The standard uses a PDCA-style structure with 10 clauses, including seven mandatory requirements, and links high-level commitments to lifecycle controls. In practice, an organization can use this structure to define decision rights, risk registers, performance indicators, escalation paths, and periodic evaluation. The overview of major AI governance frameworks places ISO/IEC 42001 in the broader standards environment.
UN General Assembly resolution
The UN resolution adopted on 21 March 2024 is a diplomatic instrument rather than a management standard. It creates shared political language around safe, secure, and trustworthy AI and calls on a wide range of actors to support governance frameworks. It doesn't replace domestic law or tell an engineer how to test a model. Its value lies in agenda-setting, coalition-building, and creating a forum where states can negotiate common expectations.
Framework | Year Updated | Binding Force | Core Function | Best Use in Debate |
OECD AI Principles | 2023 and 2024 | Intergovernmental guidance | Shared values and national policy recommendations | Establish common principles across states |
NIST AI RMF | Maintained as a risk framework | Voluntary operational guidance | Govern, Map, Measure, and Manage AI risk | Propose practical organizational controls |
ISO/IEC 42001 | Current management-system standard | Voluntary unless adopted contractually or legally | Lifecycle management and evidence-based evaluation | Discuss audits, procurement, and institutional accountability |
UN General Assembly AI resolution | 2024 | Political resolution, not a binding treaty | Multilateral cooperation and shared diplomatic language | Build consensus and frame future negotiations |
A delegate who confuses these instruments may call a voluntary framework a treaty or demand that a diplomatic resolution provide technical controls. Good debate depends on matching the tool to the problem. If the problem is organizational inconsistency, argue for governance processes. If it is fragmented national policy, invoke intergovernmental principles. If it is international coordination, use the UN forum.
The distinction also matters in international law. A resolution can influence expectations without creating the same obligations as a treaty, a point worth reviewing through this guide to international law and treaties.
Comparing the EU, U.S., and Emerging Bloc Approaches
Delegates often speak as if there were one global AI regulation text on the table. There is not. Each jurisdiction starts from a different committee room, with its own institutions, political priorities, administrative capacity, and relationship to technology firms.
The European approach is usually framed as a risk-based model. It sorts systems by the seriousness of potential harm and then adds stricter obligations where the stakes rise. That structure gives clarity, much like a draft resolution with defined clauses and annexes. The trade-off is administrative weight. Detailed requirements can be harder to carry for smaller organizations, or for states with limited capacity to supervise them.
The United States has leaned more on sectoral rules, agency action, voluntary frameworks, and state-level initiatives. That allows regulators to act within existing authority, but it can leave companies working from several rulebooks at once. The issue is practical, not abstract. It affects where a developer looks for guidance, which public body investigates a failure, and how compliance is documented after something goes wrong.
Emerging and middle-power states face a different constraint. The Chatham House analysis of global AI governance describes governments that may lack frontier AI capability, compute, technical expertise, or legal authority to test proprietary systems and compel disclosure. Some states will prioritize access to infrastructure, training data, and compute before building independent oversight systems. The analysis of barriers to global AI governance shows why copying a high-income-country rulebook is not automatically a workable solution.
Three negotiating positions
A delegate defending the European position can argue that risk tiers give the field a predictable baseline and clearer protection for affected people. A U.S.-oriented delegate can stress institutional flexibility, sector expertise, and the danger of forcing one rule onto every application. A Global South or middle-power delegate can ask who pays for implementation, who provides technical capacity, and how local languages and public-sector needs are included.
Region | Regulatory Style | Lead Authority | Core Obligation |
European Union | Risk-based and centralized in structure | EU institutions and national authorities | Match controls to the level of risk |
United States | Sectoral, agency-led, and voluntary in important areas | Federal agencies, states, and organizations | Apply existing authority and risk-management practices |
Emerging and middle-power states | Capacity-sensitive and strategically diverse | National governments and regional institutions | Expand access, build expertise, and develop workable oversight |
Implementation is where many committee speeches become real. Surveys of senior AI executives show a gap between having a formal policy and having the expertise to enforce it. A policy document can look polished on the dais and still leave an organization without the staff, inventory, or process needed to apply it consistently.
For product-focused debate, liability is a useful bridge between legal theory and engineering practice. A resource on product liability and software updates helps delegates examine how responsibility may shift when software is updated after deployment. The central negotiation is plain. How much legal certainty should governments demand, and how much flexibility should they preserve for innovation?
The Agentic AI Governance Gap
A committee approves a digital assistant to answer questions. Within weeks, that system begins searching databases, passing information between agencies, and initiating actions without waiting for a person at every step. This is the practical difference between conventional and agentic AI. A conventional system responds to a request. An agentic system pursues a goal through several steps, uses tools, routes information, and may act independently.
The governance question therefore changes. A policy can exist on paper while failing to control a system that moves faster than the organization's approval chain. In Model UN terms, delegates have drafted the resolution, but no one has assigned monitors, reporting duties, or authority to halt a violation.
The EY survey reports that 49% of organizations using agentic AI say their current governance framework has not been updated for agentic risks, while a quarter cannot detect unauthorized AI agents operating internally. The EY findings on autonomous AI oversight make the institutional problem concrete. An organization may have an ethics policy and still lack an inventory of its agents, records of their actions, or a clear chain of command.
What can go wrong
An agent could make a decision that no individual explicitly approved. It could transfer information between systems and bypass a normal review. It could trigger a financial, administrative, or operational action while responsibility is divided among the developer, deployer, user, and platform provider. The result resembles a coalition resolution with several sponsors but no agreement on who answers when implementation causes harm.
Delegates should test four questions:
- Authorization: Which actions require human approval, and which can the agent perform alone?
- Traceability: Can investigators reconstruct what the agent saw, decided, and executed?
- Containment: Can the organization suspend the agent without disabling services that people depend on?
- Liability: Which actor answers for damage caused by a chain of automated decisions?
These questions show why broad principles need operational rules. Transparency matters, but a statement about transparency will not stop an unauthorized agent. Accountability also requires a named decision-maker, usable evidence, and a procedure that works under pressure.

A draft resolution could combine several policy levers:
- Agent licensing: Require higher-risk autonomous systems to meet defined conditions before deployment.
- Sandbox registration: Let organizations test agents in controlled environments while reporting their capabilities and boundaries.
- Kill-switch mandates: Require a technically tested method for suspending an agent.
- Real-time logging: Preserve records of instructions, tool use, decisions, and human interventions.
- Action limits: Restrict an agent's authority over sensitive data, public services, or financial transactions.
AI in government examples gives students a practical setting for testing these proposals. Ask whether one safeguard can govern a public chatbot, a benefits system, and an agent that alters government records. Different answers point toward risk-sensitive rules, much like separate clauses for different country situations in a negotiated resolution.
Global South Capacity and the New Multipolar Order
AI governance isn't only a question of which rulebook is most elegant. It is also a question of who has the capacity to write, interpret, and enforce that rulebook.
A government may want strong oversight but lack access to compute, multilingual training data, technical specialists, or the legal authority to inspect a proprietary model. It may depend on technology transfer from larger powers while trying to preserve policy independence. Compliance costs can also absorb the limited resources that a lower-capacity regulator needs for actual enforcement.
That creates a diplomatic imbalance. States may be invited to endorse common principles while lacking the tools to evaluate whether companies follow them. A fair negotiation therefore needs to discuss capacity-building alongside obligations. Otherwise, “global governance” can become a request for poorer states to implement standards designed elsewhere.
From one center to several negotiating tracks
The international context is becoming more multipolar. In 2026, the UN Global Dialogue on AI Governance held its first session. China-backed WAICO launched with 29 founding members, while the U.S.-led Pax Silica framework expanded from 11 to 24 signatories. These developments, described in the Chatham House analysis, indicate that governments are building several overlapping forums rather than waiting for one institution to settle every question.

For a Model UN delegate, this is a coalition-management problem. The OECD may provide a shared values vocabulary. The UN may provide universal diplomatic legitimacy. Regional organizations may focus on infrastructure, language, public services, or strategic autonomy. State-led groupings may emphasize supply chains, security, or technology access.
A strong position paper should ask four questions:
- Representation: Which states participate in the negotiating forum?
- Capacity: Who pays for technical assistance, training, and evaluation tools?
- Sovereignty: Can a state retain control over public-sector deployments and data?
- Interoperability: How can different regional systems recognize one another's safeguards?
The answer won't be a simple choice between “global rules” and “national sovereignty.” States can cooperate on testing, incident reporting, and capacity-building while retaining authority over domestic policy. They can also disagree about surveillance, market access, infrastructure, and the role of private companies.
Read the outcome of the UN Global Dialogue as a live draft resolution, not a finished treaty. Mark every operative clause that lacks an implementing actor, a funding mechanism, or a reporting process. Then propose language that gives lower-capacity states a role beyond endorsing principles written by others.
A Student Toolkit for Policy Debate and Research
The night before caucus, a chair does not expect delegates to memorize every framework. The goal is to turn a broad AI governance topic into a draft resolution that identifies the dispute, assigns responsibility, and gives other states something they can negotiate.
Begin with a motion that places two policy priorities in tension:
- Risk-based or sectoral rules: Should states adopt a shared risk-tiered model, or should each sector write its own requirements?
- Open-weight models: Do publicly available model weights need a separate trust category, with safeguards addressing both access and misuse?
- Sovereignty and compute: Should cooperation attach conditions to advanced infrastructure access, or would those conditions deepen technological inequality?
Treat each motion as a bloc's opening position. Then convert it into a preambulatory clause:
- “Recognizing that formal policies may fail without implementation expertise...”
- “Emphasizing the need for meaningful participation by states with limited evaluation capacity...”
- “Concerned that autonomous systems may act without a clearly documented chain of command...”
- “Encouraging compatible reporting and audit practices while respecting national regulatory authority...”
A preambulatory clause explains why the committee should act. An operative clause specifies what happens next. The committee might establish a working group, request voluntary reporting, fund technical assistance, encourage model evaluation, or ask states to develop national inventories. Choose verbs that identify an actor and a task. A sentence that merely “supports” cooperation leaves delegates with no mechanism to negotiate.
A compact research ladder
Read the OECD principles first for a shared values vocabulary. Study the NIST Govern function to see how organizations translate principles into policies and evidence. Examine ISO/IEC 42001 for the management-system perspective, then read the UN resolution to observe how states frame cooperation in diplomatic language. Compare regional approaches and capacity constraints before drafting your bloc's position.
Use a source grid with four columns: claim, actor, evidence, and policy consequence. For example, a claim about evaluation capacity should identify the responsible institution, cite supporting material, and explain which policy response follows. Track official strategies, regulatory consultations, implementation guidance, and public statements separately when comparing countries. See this guide to using AI for research for methods that preserve source traceability.
Model Diplomat can support MUN and international relations research with sourced answers and structured learning resources. Use it to clarify unfamiliar institutions, then verify important claims against primary government, UN, standards, or organizational documents.

Before committee begins, write one sentence answering: What does my proposal require, who implements it, and how can another state verify that it happened? If the answer is unclear, the idea remains a principle rather than a workable policy.
Open Questions That Will Define the Next Decade
At the next Model UN session, delegates could face a draft resolution on AI rules whose language becomes outdated before the vote. Each framework is a negotiating position: one bloc may prioritize enforceable safeguards, another may defend innovation, and a third may demand greater capacity for lower-resource states. The next decade will test whether these positions produce rules that remain usable as AI systems gain autonomy and operate across borders.
Who enforces a rule when an agent acts internationally without a clear flag state? Should compute thresholds follow an arms-control model, or would that restrict countries still building technological capacity? How should liability work when one model delegates a task to another and no single human makes the final decision?
Political authority raises a second set of questions. Can a UN framework gain meaningful force without support from every major AI power? Can democratic institutions review foundation models whose internal operations remain difficult to explain? Can lower-resource states help write the rules rather than receive them as markets or technical-assistance recipients?
A delegate's neutrality also has consequences. Leaving autonomous action lightly regulated preserves flexibility while making responsibility harder to assign after harm. Strict controls may protect the public while reducing access and slowing useful deployment.
Choose one question and defend a position. Write the strongest case for the opposing bloc, identify evidence that could change your view, and draft an operative clause that could survive negotiation. Model Diplomat helps students prepare for MUN and international relations debates through sourced political research, structured learning, and diplomacy-focused practice.

